# What is stored, and what is never sent

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Reports are treated as hostile input

A vulnerability report is the one thing you receive that is deliberately an attack. Everything here follows from that.

- Report text is sanitized when it arrives, so a report cannot carry working script into your workspace.
- Attachments always download and never render, and each download is written to the audit log.
- No URL in a report is ever fetched by TotalCtrl.
- The report body is never copied into an issue, a Jira ticket, a webhook payload, or anything the AI assistant returns.

## Reporters are not users

Somebody who reports a bug is identified by an email address and a link. They hold no seat, have no password, and can reach nothing but their own reports.
## The audit trail

Every state change is recorded — who, when, from what to what, and why — and that record is never edited or deleted. It is the evidence of how a report was handled, and the disagreements a program has are all about that history.
## No payouts here

Bug Bounty does not move money. Publish your reward ranges, decide what a report is worth, and pay it through your own finance process.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Automate on reports: webhooks and the API](https://help.totalctrl.app/en-US/articles/bugbounty-api-and-webhooks-1)
- [Send reports to Issue Tracking or Jira](https://help.totalctrl.app/en-US/articles/bugbounty-trackers-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)